Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,432
Critical1,287
High4,421
Medium12,480
Reset
Showing 4221-4240 of 18432 records
Threat Entry Updated 2026-06-17

CVE-2026-25320 - Elementor Contact Form DB Plugin

Missing Authorization vulnerability in Cool Plugins Elementor Contact Form DB sb-elementor-contact-form-db allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Contact Form DB: from n/a through

PLUGIN Elementor Contact Form DB

CVE-2026-25320

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25323 - OSM Plugin

Missing Authorization vulnerability in MiKa OSM osm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OSM: from n/a through

PLUGIN OSM

CVE-2026-25323

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25319 - Zita Elementor Site Library Plugin

Cross-Site Request Forgery (CSRF) vulnerability in wpzita Zita Elementor Site Library zita-site-library allows Cross Site Request Forgery.This issue affects Zita Elementor Site Library: from n/a through

PLUGIN Zita Elementor Site Library

CVE-2026-25319

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25318 - WiserReview Product Reviews for WooCommerce Plugin

Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserReview Product Reviews for WooCommerce: from n/a through

PLUGIN WiserReview Product Reviews for WooCommerce

CVE-2026-25318

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25316 - CartFlows Plugin

Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/a through

PLUGIN CartFlows

CVE-2026-25316

HIGH CVSS 7.2 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25311 - Autoshare for Twitter Plugin

Missing Authorization vulnerability in 10up Autoshare for Twitter autoshare-for-twitter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoshare for Twitter: from n/a through

PLUGIN Autoshare for Twitter

CVE-2026-25311

MEDIUM CVSS 5.4 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25315 - WordPress Core

Improperly implemented security check vulnerability in KAGG hCaptcha for WP allows CAPTCHA Functionality Bypass.This issue affects hCaptcha for WP: from n/a through 4.21.1. The vulnerability is limited to the CAPTCHA mechanism intended to protect a publicly accessible form from automated abuse. It does not impact WordPress-level authentication or authorization controls.

CORE WordPress Core

CVE-2026-25315

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25310 - Extend Link Plugin

Server-Side Request Forgery (SSRF) vulnerability in Alobaidi Extend Link extend-link allows Server Side Request Forgery.This issue affects Extend Link: from n/a through

PLUGIN Extend Link

CVE-2026-25310

MEDIUM CVSS 4.9 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25314 - TOP Table Of Contents Plugin

Missing Authorization vulnerability in WP Messiah TOP Table Of Contents top-table-of-contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TOP Table Of Contents: from n/a through

PLUGIN TOP Table Of Contents

CVE-2026-25314

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25313 - FluentForm Plugin

Missing Authorization vulnerability in Shahjahan Jewel FluentForm fluentform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through

PLUGIN FluentForm

CVE-2026-25313

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25308 - Simple Membership Plugin

Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through

PLUGIN Simple Membership

CVE-2026-25308

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25307 - XStore Core Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.7.

PLUGIN XStore Core

CVE-2026-25307

MEDIUM CVSS 6.5 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25305 - XStore Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows DOM-Based XSS.This issue affects XStore: from n/a through

PLUGIN XStore

CVE-2026-25305

MEDIUM CVSS 6.5 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25004 - CM Business Directory Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through

PLUGIN CM Business Directory

CVE-2026-25004

MEDIUM CVSS 5.9 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25006 - XStore Plugin

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through

PLUGIN XStore

CVE-2026-25006

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25005 - Frontend File Manager Plugin

Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through

PLUGIN Frontend File Manager

CVE-2026-25005

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25008 - Ninja Tables Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Retrieve Embedded Sensitive Data.This issue affects Ninja Tables: from n/a through

PLUGIN Ninja Tables

CVE-2026-25008

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-25003 - Client Portal Plugin

Missing Authorization vulnerability in madalin.ungureanu Client Portal client-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Portal: from n/a through

PLUGIN Client Portal

CVE-2026-25003

MEDIUM CVSS 4.3 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-23805 - Media Search Enhanced Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media Search Enhanced media-search-enhanced allows SQL Injection.This issue affects Media Search Enhanced: from n/a through

PLUGIN Media Search Enhanced

CVE-2026-23805

HIGH CVSS 7.6 2026-02-19
Threat Entry Updated 2026-06-17

CVE-2026-23803 - Smart Auto Upload Images Plugin

Server-Side Request Forgery (SSRF) vulnerability in Burhan Nasir Smart Auto Upload Images smart-auto-upload-images allows Server Side Request Forgery.This issue affects Smart Auto Upload Images: from n/a through

PLUGIN Smart Auto Upload Images

CVE-2026-23803

MEDIUM CVSS 6.4 2026-02-19
Scroll to top